PT-2014-6152 · Ibm · Ibm Websphere Commerce

Publicado

2014-11-05

·

Atualizado

2019-09-30

·

CVE-2014-4834

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions IBM WebSphere Commerce versions 6.x through 6.0.0.11 IBM WebSphere Commerce versions 7.x through 7.0.0.8
Description The issue allows remote attackers to cause a denial of service, resulting in memory and CPU consumption, and application crash, via a crafted XML document containing a large number of nested entity references.
Recommendations For IBM WebSphere Commerce versions 6.x through 6.0.0.11, update to a version that properly detects recursion during entity expansion to prevent denial of service attacks. For IBM WebSphere Commerce versions 7.x through 7.0.0.8, update to a version that properly detects recursion during entity expansion to prevent denial of service attacks.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2014-4834

Produtos afetados

Ibm Websphere Commerce